Skip to content

chore: add trivy to the lint stack - #121

Draft
iloveitaly wants to merge 4 commits into
masterfrom
cursor/add-trivy-lint-b697
Draft

iloveitaly wants to merge 4 commits into
masterfrom
cursor/add-trivy-lint-b697

Conversation

@iloveitaly

@iloveitaly iloveitaly commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Motivation

The lint stack already covers secrets in git history with gitleaks, but it does not scan dependency advisories or infrastructure misconfiguration. Trivy covers that working-tree gap.

Description

  • Install Trivy with mise (aqua:aquasecurity/trivy, locked at 0.74.0) as a dev/CI tool.
  • Run trivy fs --config .config/trivy.yaml . from just dev_lint, which just lint and the backend CI job already call.
  • Policy lives in .config/trivy.yaml: HIGH and CRITICAL only, ignore unfixed advisories, include dev dependencies, and scan vulnerabilities, misconfigurations, and secrets. Vendored mise locks and node_modules are skipped.
  • Cache ~/.cache/trivy in the backend workflow so the vulnerability database is not downloaded on every run.
  • Keep the public Dokku ingress and the Terraform state storage account reachable. Those resources are intentional, so the matching Trivy checks are ignored inline.
  • Pin brace-expansion, js-yaml, and shell-quote in web/pnpm-workspace.yaml so the new gate is green.

Screenshots / Test

just dev_lint exits 0. gitleaks reports no leaks, and the Trivy report shows 0 high or critical vulnerabilities, misconfigurations, and secrets for uv.lock, web/pnpm-lock.yaml, and infra/azure. Trivy logs Loaded file_path=".config/trivy.yaml".

Links

Open in Web Open in Cursor 

cursoragent and others added 4 commits September 26, 2026 17:58
Scan the working tree for high and critical vulnerabilities, misconfigurations, and secrets from just dev_lint, alongside gitleaks.

Co-authored-by: Michael Bianco <mike@mikebian.co>
Override brace-expansion, js-yaml, and shell-quote so the Trivy lint gate passes on the current lockfile.

Co-authored-by: Michael Bianco <mike@mikebian.co>
Point just dev_lint at .config/trivy.yaml with --config.

Co-authored-by: Michael Bianco <mike@mikebian.co>
The Trivy gate now flags 1.1.18, 2.1.4, and 5.0.9. Pin the fixed releases.

Co-authored-by: Michael Bianco <mike@mikebian.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants